3 ms·
Yeah I was having the same thought on the web form and if it brings additional overhead maintenance, testing, etc which to me would be the same as trying to get
by ZeroSolstice 3y ago
Yeah I was having the same thought on the web form and if it brings additional overhead maintenance, testing, etc which to me would be the same as trying to get some form of PGP working across mail clients.
> Having said that, if the problem is the limited PGP infrastructure then I don't see how an ad-hoc protocol that uses the same certificates as the site's HTTPS cert is going to get more adoption.
This is the only part I would disagree with and it could be subjective based on your experience with certificates. Using openssl wouldn't really be ad-hoc as this is what certificates are for. If the researcher and the website owner already have certificates for their websites there isn't any other additional work as both public keys are available in the form of their site certificates. There are also a number of sites that provide instructions on generating self-signed certificates [1][2][3] as well as encrypting messages with public certs [4][5][6].
Oddly enough when looking for the (3) openssl commands for encrypting a message I came across this site which recommended using GPG for messages[4], however they all pre-suppose that you have everything setup for using GPG which usually isn't the case and using openssl, in my opinion, has reduced friction being as it doesn't depend on being integrated into a web or email client application, you can simply attach the generated encrypted message like any other email attachment.
The infrastructure concern is really the existing public key availability, accessibility and maintenance options for keys. If the public service is unreliable or lacking robustness then both software developers and individuals are less likely to use or integrate the implementation. There are only a few places to upload your pgp key to that are reliable, compared to the existing certificate system. On my last looking there were maybe (3) sites that were reliable[7] and MIT had been flaky for a while, leaving only two.
https://pgp.mit.edu/ https://pgp.mit.edu/
https://keyserver.ubuntu.com/ https://keyserver.ubuntu.com/
https://keys.openpgp.org/ https://keys.openpgp.org/
However, to your initial point I can certainly see a web interface being a better overall solution as the people set to receive these notifications may not be familiar with the command line or terminal interfaces let alone openssl commands.
Thanks for your response I enjoyed thinking through this.
----
References
[1] https://msol.io/blog/tech/create-a-self-signed-ssl-certificate-with-openssl/ https://msol.io/blog/tech/create-a-self-signed-ssl-certifica...
[2] https://devopscube.com/create-self-signed-certificates-openssl/ https://devopscube.com/create-self-signed-certificates-opens...
[3] https://www.digitalocean.com/community/tutorials/openssl-essentials-working-with-ssl-certificates-private-keys-and-csrs https://www.digitalocean.com/community/tutorials/openssl-ess...
[4] https://www.madboa.com/geek/openssl/#how-do-i-simply-encrypt-a-file https://www.madboa.com/geek/openssl/#how-do-i-simply-encrypt...
[5] https://gist.github.com/thinkerbot/706137 https://gist.github.com/thinkerbot/706137
[6] https://www.czeskis.com/random/openssl-encrypt-file.html https://www.czeskis.com/random/openssl-encrypt-file.html
[7] https://superuser.com/questions/227991/where-to-upload-pgp-public-key-are-keyservers-still-surviving https://superuser.com/questions/227991/where-to-upload-pgp-p...